News: 1659682627

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Critical flaws found in four Cisco SMB router ranges – for the second time this year

(2022/08/05)


Cisco has revealed four of its small business router ranges have critical flaws – for the second time in 2022 alone.

A Wednesday [1]advisory warns owners of the RV160, RV260, RV340, and RV345 Series Routers that the vulnerabilities could allow "an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device."

The four ranges were whacked with three 10/10 bugs in [2]February 2022 .

[3]

This time around the worst of the bugs – CVE-2022-20842 – is rated 9.8/10 on the Common Vulnerability Scoring System (CVSS).

Exploitation of one vulnerability may be required to exploit another

Cisco says a vulnerability in the web-based management interface of the RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow execution of arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service condition. "This vulnerability is due to insufficient validation of user-supplied input to the web-based management interface," Cisco states.

[4]Cisco compresses Catalyst switches to compact size

[5]Cisco quits Moscow

[6]Cisco warns of security holes in its security appliances

CVE-2022-20827 is rated 9/10 and applies to all four of the abovementioned router ranges.

Cisco describes the flaw as "A vulnerability in the web filter database" that "could allow an unauthenticated, remote attacker to perform a command injection and execute commands on the underlying operating system with root privileges.

[7]

[8]

"This vulnerability is due to insufficient input validation," Cisco adds, and means an attacker submitting crafted input to the web filter database update feature and then execute commands on the underlying operating system with root privileges.

At a mere 8.3/10 CVE-2022-20841 is rated a mere "high" risk bug, rather than the "critical" status of the two CVEs mentioned above.

[9]

"This vulnerability is due to insufficient validation of user-supplied input,” states Cisco's explanation of the mess, once again. "An attacker could exploit this vulnerability by sending malicious input to an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system. To exploit this vulnerability, an attacker must leverage a man-in-the-middle position or have an established foothold on a specific network device that is connected to the affected router."

Patching all three flaws – ASAP – is advised because Cisco warns "The vulnerabilities are dependent on one another."

"Exploitation of one of the vulnerabilities may be required to exploit another vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities."

[10]

At least owners of the devices (should) have recent experience patching the borked boxen.

Another small mercy is that Cisco's not advised binning the products, as it did for its [11]RV110W, RV130, RV130W, and RV215W routers only a couple of months ago.

Of course, users tired of updating small business routers might decide to do so without Cisco's suggestion. ®

Get our [12]Tech Resources



[1] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-mult-vuln-CbVp4SUR?emailclick=CNSemail

[2] https://www.theregister.com/2022/02/04/cisco_smb_routers_critical_vulnerabilities/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YuzqSAbTBDhx9Fn4djQr8QAAAIU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2022/06/28/catalyst_9200_compact/

[5] https://www.theregister.com/2022/06/24/cisco_quits_russia_and_belarus/

[6] https://www.theregister.com/2022/06/22/cisco_bug_bundle/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuzqSAbTBDhx9Fn4djQr8QAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuzqSAbTBDhx9Fn4djQr8QAAAIU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuzqSAbTBDhx9Fn4djQr8QAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuzqSAbTBDhx9Fn4djQr8QAAAIU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2022/06/16/cisco_critical_patches/

[12] https://whitepapers.theregister.com/



Anonymous Coward

I hope governments are putting in place plans to remove Cisco products from our core infrastructure.

pavel.petrman

I had similar thought but in different direction: one feels that Cisco's software must be full of bugs, Juniper as well, Aruba at least half full (call me an optimist here), even Fortinet get their laundry publicly wasched every now and then. But so far I haven't heard about one public announcement of a vulnerability in Huawei's infrastructure gear (consumer gear and endpoint appliances do get mentioned from time to time).

I'm curious why. Do they disclose their vulnerabilities in a similar manner as Cisto et al? If yes, why they don't get similar media coverage? If not, why? Is it a cultural difference or a language barrier?

I'd hazard a guess that Huawei gear gets updates and patches as well. There are lots and lots of Huawei boxes installed throughout Europe. Is there a Huawei admin here on this forum, who could chip in with a real world experience?

jeffty

Not a Huawei admin, but looking at their site it appears they operate a PSIRT (Product Security Incident Response Team) and disclose bugs/security issues in much the same way as the other vendors (admins can subscribe via RSS or email normally to get updates via the medium of their choice).

Used to review this kind of thing weekly in a previous role (security-focused) where we'd be checking all of our known infrastructure to see if any exploits had been announced against the various hardware/software we ran internally.

Paul Crawford

They got roasted for rubbish software, but not any real "back doors":

https://www.theregister.com/2019/03/28/hcsec_huawei_oversight_board_savaging_annual_report/

You could argue you don't need back doors with many broken windows and loose hinges, of course. But in Huawei's defence their code was audited for this where as the others like Cisco, etc, have not, and the public evidence of so many critical CVE suggest they can't be a whole lot better.

When will we learn?

Mike 137

CVE-2022-20842 "due to insufficient validation of user-supplied input"

CVE-2022-20827 "due to insufficient input validation"

CVE-2022-20841 "due to insufficient validation of user-supplied input"

Never trust input data (even if you've supplied it yourself). Allow only what is expected and required.

Life, like beer, is merely borrowed.
-- Don Reed